CVE-2024-41049

Source
https://cve.org/CVERecord?id=CVE-2024-41049
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-41049.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-41049
Downstream
Related
Published
2024-07-29T14:32:05.953Z
Modified
2026-03-13T07:56:07.833078Z
Summary
filelock: fix potential use-after-free in posix_lock_inode
Details

In the Linux kernel, the following vulnerability has been resolved:

filelock: fix potential use-after-free in posixlockinode

Light Hsieh reported a KASAN UAF warning in traceposixlock_inode(). The request pointer had been changed earlier to point to a lock entry that was added to the inode's list. However, before the tracepoint could fire, another task raced in and freed that lock.

Fix this by moving the tracepoint inside the spinlock, which should ensure that this doesn't happen.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41049.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
117fb80cd1e63c419c7a221ce070becb4bfc7b6d
Fixed
1cbbb3d9475c403ebedc327490c7c2b991398197
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a6f4129378ca15f62cbdde09a7d3ccc35adcf49d
Fixed
7d4c14f4b511fd4c0dc788084ae59b4656ace58b
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
766e56faddbec2eaf70c9299e1c9ef74d846d32b
Fixed
02a8964260756c70b20393ad4006948510ac9967
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
34bff6d850019e00001129d6de3aa4874c2cf471
Fixed
5cb36e35bc10ea334810937990c2b9023dacb1b0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
74f6f5912693ce454384eaeec48705646a21c74f
Fixed
432b06b69d1d354a171f7499141116536579eb6a
Fixed
116599f6a26906cf33f67975c59f0692ecf7e9b2
Fixed
1b3ec4f7c03d4b07bad70697d7e2f4088d2cfe92
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
e75396988bb9b3b90e6e8690604d0f566cea403a

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-41049.json"